PT-2026-29603 · Aiohttp+3 · Aiohttp+3

·

CVE-2026-34514

·

Published

2026-02-21

·

Updated

2026-08-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.13.4
Description AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. An attacker controlling the content type parameter in aiohttp could inject extra headers or similar exploits. If an application allows untrusted data to be used for the multipart content type parameter when constructing a request, an attacker may be able to manipulate the request.
Recommendations Update to version 3.13.4 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-81761
BDU:2026-09572
CLEANSTART-2026-AN24336
CLEANSTART-2026-AN27706
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-FU07345
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-34514
ECHO-2E96-17F7-CC4B
GHSA-2VRM-GR82-F7M5
OESA-2026-2192
OESA-2026-2193
OESA-2026-2194
OPENSUSE-SU-2026:10490-1
OPENSUSE-SU-2026:21098-1
PYSEC-2026-2096
SUSE-SU-2026:22173-1
SUSE-SU-2026:3059-1
SUSE-SU-2026:3207-1
USN-8591-1

Affected Products

Aiohttp
Linuxmint
Red Os
Ubuntu